BIT-tensorflow-2020-26269

    Dashboard / Vulnerabilities / BIT-tensorflow-2020-26269

    BIT-tensorflow-2020-26269

    Published: 6 Mar 2024Last Modified: 20 May 2025

    Summary: Heap out of bounds read in filesystem glob matching in TensorFlow

    Details: In TensorFlow release candidate versions 2.4.0rc*, the general implementation for matching filesystem paths to globbing pattern is vulnerable to an access out of bounds of the array holding the directories. There are multiple invariants and preconditions that are assumed by the parallel implementation of GetMatchingPaths but are not verified by the PRs introducing it (#40861 and #44310). Thus, we are completely rewriting the implementation to fully specify and validate these. This is patched in version 2.4.0. This issue only impacts master branch and the release candidates for TF version 2.4. The final release of the 2.4 release will be patched.

    Affected packages

    Package

    Name: tensorflow

    Purl: pkg:bitnami/tensorflow

    Affected ranges

    Type: SEMVER

    Events:

    Introduced- 2.4.0-rc0
    Fixed -2.4.0

    Affected versions

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High
    BIT-tensorflow-2020-26269 | CVE-DB